Educational information only. Not financial advice. Crypto is volatile. Verify sources and decide for yourself.

Signing-system attack

Plain definition. A signing-system attack exploits how the XRP Ledger checks signatures. One flaw found in February 2026 could have let an attacker move other people’s funds without their private keys.

Technical definition. XRPL Labs described this kind of attack in its February 2026 disclosure report on a “critical logic flaw in the signature-validation logic of the XRPL Batch amendment.” Under Batch, inner transactions are intentionally unsigned, and authorization rests entirely on the outer batch’s list of batch signers. The validating function stopped at the first signer whose account did not yet exist and whose key matched that account, and treated the check as passed. That meant a forged signer entry claiming to authorize a victim, but signed with the attacker’s own key, was never checked. The victim’s payment would then execute without the victim’s keys, though the amendment had not been activated on mainnet and no funds were at risk.

On this site

On this site, Signing-system attack comes up in How do crypto exchanges actually get hacked if they use cold wallets?, What happened in the September 2026 Bitget theft, and were customers’ funds affected?, How much should I keep in a hot wallet versus cold storage? and What is air-gapped signing, and do I need it?.

Source

Vulnerability Disclosure Report: XRPL Batch Amendment – Unauthorized Inner Transaction Execution (xrpl.org), read October 1, 2026.

Pages that cover Signing-system attack